Show plain JSON{"id": "CVE-2015-7450", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 10.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C", "authentication": "NONE", "integrityImpact": "COMPLETE", "accessComplexity": "LOW", "availabilityImpact": "COMPLETE", "confidentialityImpact": "COMPLETE"}, "acInsufInfo": false, "impactScore": 10.0, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}, {"type": "Secondary", "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}]}, "published": "2016-01-02T21:59:15.800", "references": [{"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21970575", "tags": ["Vendor Advisory"], "source": "psirt@us.ibm.com"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21971342", "tags": ["Vendor Advisory"], "source": "psirt@us.ibm.com"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21971376", "tags": ["Vendor Advisory"], "source": "psirt@us.ibm.com"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21971733", "tags": ["Broken Link"], "source": "psirt@us.ibm.com"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21971758", "tags": ["Vendor Advisory"], "source": "psirt@us.ibm.com"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21972799", "tags": ["Vendor Advisory"], "source": "psirt@us.ibm.com"}, {"url": "http://www.securityfocus.com/bid/77653", "tags": ["Broken Link", "Third Party Advisory", "VDB Entry"], "source": "psirt@us.ibm.com"}, {"url": "http://www.securitytracker.com/id/1035125", "tags": ["Broken Link", "Third Party Advisory", "VDB Entry"], "source": "psirt@us.ibm.com"}, {"url": "https://www.exploit-db.com/exploits/41613/", "tags": ["Exploit", "Third Party Advisory", "VDB Entry"], "source": "psirt@us.ibm.com"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21970575", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21971342", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21971376", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21971733", "tags": ["Broken Link"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21971758", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21972799", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/77653", "tags": ["Broken Link", "Third Party Advisory", "VDB Entry"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securitytracker.com/id/1035125", "tags": ["Broken Link", "Third Party Advisory", "VDB Entry"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://www.exploit-db.com/exploits/41613/", "tags": ["Exploit", "Third Party Advisory", "VDB Entry"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-502"}]}, {"type": "Secondary", "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "description": [{"lang": "en", "value": "CWE-502"}]}], "descriptions": [{"lang": "en", "value": "Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library."}, {"lang": "es", "value": "Interfaces de objetos serializados en determinados productos IBM analytics, business solutions, cognitive, IT infrastructure y mobile and social permiten a atacantes remotos ejecutar comandos arbitrarios a trav\u00e9s de un objeto Java serializado manipulado, relacionado con la clase InvokerTransformer en la librer\u00eda Apache Commons Collections."}], "lastModified": "2025-02-12T19:25:19.023", "cisaActionDue": "2022-07-10", "cisaExploitAdd": "2022-01-10", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:ibm:sterling_b2b_integrator:5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F805BA3A-178D-416E-9DED-4258F71A17C8"}, {"criteria": "cpe:2.3:a:ibm:sterling_integrator:5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8597A678-3633-4F5D-95A9-5AAB168F92B7"}, {"criteria": "cpe:2.3:a:ibm:tivoli_common_reporting:2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F56C076E-A4FB-432F-A7CB-0C37CDEC94C0"}, {"criteria": "cpe:2.3:a:ibm:tivoli_common_reporting:2.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "393AB012-4F9C-4893-827E-4480AEC16DE5"}, {"criteria": "cpe:2.3:a:ibm:tivoli_common_reporting:2.1.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A792593C-B2D4-425D-9EC4-3581A77474B5"}, {"criteria": "cpe:2.3:a:ibm:tivoli_common_reporting:3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7A1B8DFB-2004-4449-A4A7-802662D571EB"}, {"criteria": "cpe:2.3:a:ibm:tivoli_common_reporting:3.1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F1938833-B19E-4DF2-8E2C-E2ADE876D44B"}, {"criteria": "cpe:2.3:a:ibm:tivoli_common_reporting:3.1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2DBE91DF-8844-4ADB-AC02-839305F82B0F"}, {"criteria": "cpe:2.3:a:ibm:tivoli_common_reporting:3.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BED14B09-F9FF-4DB4-9404-0D3A2BAC7FDD"}, {"criteria": "cpe:2.3:a:ibm:tivoli_common_reporting:3.1.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5D680D54-EE53-4658-98E1-64F316D23177"}, {"criteria": "cpe:2.3:a:ibm:watson_content_analytics:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "18D82CA9-8AFE-44FF-956C-F2B8E42B3EB4", "versionEndIncluding": "3.0.0.6", "versionStartIncluding": "3.0"}, {"criteria": "cpe:2.3:a:ibm:watson_content_analytics:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B22F02C8-BF16-4202-82B7-E167E0F6FC75", "versionEndIncluding": "3.5.0.3", "versionStartIncluding": "3.5"}, {"criteria": "cpe:2.3:a:ibm:watson_explorer_analytical_components:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "58412A55-8780-417E-9E89-AF9F5DD19BC4", "versionEndIncluding": "10.0.0.2", "versionStartIncluding": "10.0"}, {"criteria": "cpe:2.3:a:ibm:watson_explorer_analytical_components:11.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8AAD3A69-115D-4D6C-B5A9-7590E97B15A9"}, {"criteria": "cpe:2.3:a:ibm:watson_explorer_annotation_administration_console:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "41147B26-C469-48EE-B139-C0D0B07BBDED", "versionEndIncluding": "10.0.0.2", "versionStartIncluding": "10.0"}, {"criteria": "cpe:2.3:a:ibm:watson_explorer_annotation_administration_console:11.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "66634C1B-0E8A-48FD-A0DC-D5AD4CF29EC7"}, {"criteria": "cpe:2.3:a:ibm:websphere_application_server:7.0.0.0:*:*:*:-:*:*:*", "vulnerable": true, "matchCriteriaId": "A0507670-6059-4164-AD54-A5172DE8313F"}, {"criteria": "cpe:2.3:a:ibm:websphere_application_server:8.0.0.0:*:*:*:-:*:*:*", "vulnerable": true, "matchCriteriaId": "A207B0AA-DF2F-4B1B-9D87-D812E33ADBD0"}, {"criteria": "cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:traditional:*:*:*", "vulnerable": true, "matchCriteriaId": "6C43FBAC-2DD2-43CB-AC5F-56741BB2A31C"}, {"criteria": "cpe:2.3:a:ibm:websphere_application_server:8.5.0.0:*:*:*:hypervisor:*:*:*", "vulnerable": true, "matchCriteriaId": "AB001073-3FE0-452B-94FB-57B4555F7CE9"}, {"criteria": "cpe:2.3:a:ibm:websphere_application_server:8.5.5.5:*:*:*:liberty:*:*:*", "vulnerable": true, "matchCriteriaId": "3029A691-2288-453A-8FC0-7598EF60357C"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@us.ibm.com", "cisaRequiredAction": "Apply updates per vendor instructions.", "cisaVulnerabilityName": "IBM WebSphere Application Server and Server Hypervisor Edition Code Injection."}